mediumMultiple ChoiceObjective-mapped
CRISC Practice Question: A university's IT department is implementing a…
A university's IT department is implementing a single sign-on (SSO) solution for students and faculty. The solution will integrate with existing Active Directory and a cloud-based learning management system (LMS). During risk identification, the team learns that the SSO vendor had a minor security incident last year. The university's security policy requires multi-factor authentication (MFA) for all administrative access, but the SSO solution does not support MFA for student accounts. The project manager insists that MFA for students is not necessary because they only access academic records. The risk team must identify the most significant risk that could affect the university's reputation. Which risk should be documented?
⚠ Common exam trap
The trap here is that candidates focus on the vendor's past incident (Option A) as a red flag, but the real risk is the missing MFA control for student accounts, which directly enables unauthorized access to sensitive data and reputational damage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Without MFA, student accounts could be compromised to access sensitive academic data.
The most significant reputational risk is that without MFA, student accounts are vulnerable to credential theft or brute-force attacks. If an attacker compromises a student account, they could access sensitive academic records (e.g., grades, personal data) protected under FERPA, leading to data breaches, legal penalties, and loss of public trust. The SSO vendor's past incident is less relevant because it was minor and does not directly expose the university's data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SSO vendor's historical security incident could impact service availability.
Why it's wrong here
Availability impact is less likely to cause reputational harm.
- ✗
Students may share passwords, leading to account compromise.
Why it's wrong here
Password sharing is a concern but not the most significant risk.
- ✗
Lack of MFA for administrative accounts could allow unauthorized changes.
Why it's wrong here
Policy already requires MFA for admin accounts.
- ✓
Without MFA, student accounts could be compromised to access sensitive academic data.
Why this is correct
Compromised student accounts can lead to data breach and reputational damage.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.